Executive brief
Adobe Acrobat Reader is vulnerable to an out-of-bounds write flaw that allows arbitrary code execution when a user opens a specially crafted PDF file. An attacker can exploit this to run malicious code with the same privileges as the user viewing the document, potentially compromising sensitive data or taking over the system.
Technical details
The vulnerability is an out-of-bounds write flaw in Adobe Acrobat Reader that enables arbitrary code execution in the context of the current user. Exploitation requires user interaction—specifically, the victim must open a malicious PDF file. The out-of-bounds write occurs during PDF parsing or processing, allowing an attacker to corrupt memory and redirect execution flow. No patch availability information is currently available from the advisory.
Affected products
- Adobe Acrobat Reader <UNKNOWN>
Timeline
- 2026-09-08: disclosed